Hidden Threats: The Dark Side of Crypto Trading Extensions
The Emergence of Crypto Copilot
In June 2025, a Chrome extension known as Crypto Copilot emerged on the digital landscape, marketed as a convenient trading assistant for Solana users. What seemed like a helpful tool quickly revealed itself to be a wolf in sheep’s clothing, stealthily siphoning off SOL from unsuspecting traders. This case exemplifies the sophisticated methods used by cybercriminals to infiltrate and exploit the growing world of cryptocurrency.
Discovery by Cybersecurity Experts
The cybersecurity firm Socket played a pivotal role in uncovering the malicious activities associated with Crypto Copilot. Through continuous monitoring of the Chrome Web Store, Socket researchers identified that the extension utilized obfuscated code and an incorrectly spelled backend domain to conceal its true purpose. According to security engineer Kush Pandya, this extension appended undisclosed fees to every transaction, amounting to a minimum of 0.0013 SOL or 0.05% of the total trade, directed to an attacker-controlled wallet.
How the Attacks Unfolded
Upon further analysis, it became clear that each time a user executed a token swap via Raydium, Crypto Copilot inserted a hidden fee transaction. Users believed they were simply swapping tokens, but the extension quietly added an extra step directing funds to the attacker’s wallet. This duplicity left users unaware that they were paying more than intended.
Indicators of Malicious Intent
Pandya’s research revealed several telltale signs of the extension’s malicious nature. Factors included aggressive code obfuscation, hardcoding of a Solana address in transaction logic, and discrepancies between the extension’s claimed functionality and its actual behavior on the blockchain. Such indicators prompted deeper investigations, confirming the hidden fee mechanism.
Risks in Browser-Based Crypto Tools
The revelation raises alarms about the vulnerabilities inherent in browser-based crypto tools, particularly those that combine social functionality with transaction initiation capabilities. The relative ease with which attackers can mask their operations speaks volumes about the need for heightened scrutiny of plugins that handle sensitive financial transactions.
A Faustian Bargain in the Chrome Web Store
Despite the alarming findings, Crypto Copilot remained available on the Chrome Web Store for months, misleading users who thought they were enhancing their trading experience. The fees that the extension imposed were never disclosed in its marketing materials or the extension listing, leading many to unwittingly absorb costs that could scale considerably with the size of their trades.
Scaling of the Malicious Mechanism
The fee structure of Crypto Copilot is particularly insidious. Swaps under 2.6 SOL trigger a flat fee of 0.0013 SOL, while larger trades apply a percentage-based fee. For instance, a 100 SOL swap would result in a hefty 0.05 SOL reduction from the user’s total—the equivalent of about $10 at prevailing market rates.
The Web of Deceit
Compounding the threat, the primary domain associated with Crypto Copilot is parked on GoDaddy, casting further doubts on its legitimacy. The secondary domain, intended to act as its backend, displays only a blank page, indicating either negligence or a calculated effort to mask its true functionality.
Ongoing Risks and User Recommendations
As of the latest updates, Socket had submitted a takedown request to Google’s Chrome Web Store to remove Crypto Copilot, but the extension was still operational at the time. Users have been advised to be vigilant, reviewing transaction instructions meticulously before signing off and steering clear of closed-source trading extensions that require signing permissions.
Trends in Malware: A Growing Concern
Unfortunately, Crypto Copilot is not an isolated incident. Malware continues to be a rampant issue in the crypto space. Recent examples include the ModStealer strain, which has targeted crypto wallets across multiple operating systems, showcasing the ever-evolving strategies employed by cybercriminals.
The ongoing developments in cyber threats highlight the pressing necessity for crypto users to remain informed and cautious in their digital dealings, especially when it involves financial transactions. In this landscape of rapid technological advancement, awareness and vigilance are more crucial than ever.

